GauntClick
Exploit Weaponization Expert
LEVEL 1
400 XP
data:image/s3,"s3://crabby-images/45fcf/45fcf4dab9875058c5583ef8bd63c191a20e525d" alt="C2EBAB96-9A8C-4519-90FE-924B77378417.png"
Hey Folks, in this tutorial we will show you how we can crack passwords of any zip file in few second. In this tutorial we will uses more than one software or tools to recover forgotten ZIP password. As we know that removal of a password from an encrypted zip file can be easy or hard depending on the complexity of the password but these kind of tool are uses dictionary file for cracking the passwords.
Requirements
Kali Linux = ( Version 2020.1 )
Lets take a look
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: 🙂"
Protect ZIP File
Now first we will protect our zip file with any random string by using the following command.
Usage
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: 🙂"
zip --password shubham@# crack2.zip file1.txt file.txt rep.txt1zip--password shubham@# crack2.zip file1.txt file.txt rep.txt
data:image/s3,"s3://crabby-images/45716/45716d052eebd80dd07d67113b1950fc3a3ef5af" alt="create-first.png"
Zip2john
Zip2john create the hashes of any zip file after that john can crack it. By using the following command we can save the output in txt file format.
zip2john crack.zip > zip.hashes1zip2john crack.zip>zip.hashes
data:image/s3,"s3://crabby-images/5ef1b/5ef1ba5bfe95da83098af7a9252a5aa1995552ab" alt="1-18.png"
We have successfully got the hash which you can see by the cat command.
cat zip.hashes1cat zip.hashes
data:image/s3,"s3://crabby-images/a0687/a0687ca541d58ab4d0fc3c364ce713b2fd27524f" alt="2-15.png"
John the Ripper
John the Ripper is a free password cracking software tool that is commonly found in Linux or Windows. It can also be to crack passwords of Compressed files like ZIP and also Documents files like PDF. It can be run against various encrypted password and hashes.
After obtain the hashes we will uses john the ripper tool which will uses his default dictionary to crack the hashes.
Usage
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: 🙂"
john zip.hashes1john zip.hashes
data:image/s3,"s3://crabby-images/5ef47/5ef471816b0523680d07d9853b3928e5fd5332e9" alt="3-16.png"
It will try a bunch of passwords to crack the hash and when it successfully gets the key it will return the result to you.
7zip-Crack
7zip-Crack is the open source tool that is listed on github page. Again It uses the dictionary to find the right key of the password protected zip file but in this tool we have to add our custom wordlist. We need to setup this tool using the following command.
git clone https://github.com/Goron/7zip-crack.git
cd 7zip-crack
chmod +x *
./7zip-crack1234git clone
https://github.com/Goron/7zip-crack.gitcd7zip-crackchmod+x *./7zip-crack
data:image/s3,"s3://crabby-images/056cb/056cbf07bf46b22d8e6613d908056d813848f710" alt="4-18.png"
As you can see above we can operate this tool easily and similarly we can crack the password of zip file by using the following command.
7zip-crack < zip file > < wordlist >17zip-crack<zip file><wordlist>
data:image/s3,"s3://crabby-images/dd40c/dd40c3f1c4edab82774baa6b9db445001345a3b9" alt="5-14.png"
Fcrackzip
Fcrackzip is the another third party tool which is especially designed to cracking zip file passwords. Fcrackzip is one of the best tool to crack the zip file password because it’s provided multiple facilities that can be helpful for crack the passphrase.
First we will download this tool from the official website.
wget http://ftp.br.debian.org/debian/pool/main/f/fcrackzip/fcrackzip_1.0-10_amd64.deb1wget http://ftp.br.debian.org/debian/pool/main/f/fcrackzip/fcrackzip_1.0-10_amd64.deb
data:image/s3,"s3://crabby-images/e0fcd/e0fcd932b4a9e60a38ea20bae89514f250eaad0e" alt="6-13.png"
After depackages this tool it will automatically added on binary’s and after that we can start by enter only the name of this tool on terminal.
sudo dpkg -i fcrackzip_1.0-10_amd64.deb1sudo dpkg-ifcrackzip_1.0-10_amd64.deb
data:image/s3,"s3://crabby-images/f09fb/f09fbbc8f947fd44c7a42aef5b9eaddb09c29808" alt="7-12.png"
Now lets we will try to crack our password protected zip file by this tool using the following command.
Usage
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: 🙂"
- -D = Dictionary
- -p = password list
- -u = exclude wrong password
fcrackzip -D -p /usr/share/john/password.lst -u crack2.zip1fcrackzip-D-p/usr/share/john/password.lst-ucrack2.zip
data:image/s3,"s3://crabby-images/ae90a/ae90a30a87a12248d9c307cb652c692a46b89f69" alt="8-10.png"
ZIP-Password-Brute Force
ZIP-Password-Brute Force tool is an open source tool which is available for both Window and Linux. First we need to setup this tool by using the following command.
git clone https://github.com/The404Hacking/ZIP-Password-BruteForcer.git
cd ZIP-Password-BruteForcer
python ZIP-Password-BruteForcer.py123git clone
https://github.com/The404Hacking/ZIP-Password-BruteForcer.gitcd ZIP-Password-BruteForcerpython ZIP-Password-BruteForcer.py
data:image/s3,"s3://crabby-images/6e9c6/6e9c677738be81103fe6eabf2bddef3c38f8c840" alt="9-9.png"
As you can see below, this tool takes few seconds to crack the password protected zip file.
data:image/s3,"s3://crabby-images/dd2b5/dd2b59e314719094e3a69caad6ae207bf35fd467" alt="10-8.png"
Zip-Cracker
Zip-Cracker is great tool for crack the encrypted zip files. This is open
data:image/s3,"s3://crabby-images/fb6a7/fb6a759b4201d7fcb73e8b4e72ac58a2ea97c0d4" alt="Unlocked :unlock: 🔓"
git clone https://github.com/lamanihani/zip-cracker.git
cd zip-cracker/
python3 crack.py123git clone
https://github.com/lamanihani/zip-cracker.gitcd zip-cracker/python3 crack.py
data:image/s3,"s3://crabby-images/536f4/536f403d0ff0e53ceb1bf94e6bbb04e7a30af346" alt="11-7.png"
After executing the above command we are ready to start this tool. Now here we need to enter the location of protected zip file.
data:image/s3,"s3://crabby-images/dd276/dd276a008136cced9db1d2ed0d8839541d084cbc" alt="12-6.png"
After giving the dictionary it will easily crack the password of zip file.
data:image/s3,"s3://crabby-images/0c4d8/0c4d838e4ed1a8bc253f12d022ee1bcc2fdccd81" alt="13-6.png"
hApPy HaCkInG
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: 🙂"
About the AuthorShubham Goyal Certified Ethical Hacker, information security analyst, penetration tester and researcher. Can be Contact on Linkedin.